22 CVEs published June 13, 2026: 2 critical, 7 high, 9 medium, 4 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 0 awaiting enrichment.
Yesterday's Results
How to read these box scores · glossary
22 CVEs published. 22 box scores, 0 table rows — nothing truncated.
D-Link DCS-935L HTTP rhea snprintf format string
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0058 45.3 —
AFFECTED
Product Versions Fixed
DCS-935L 1.10.01 – —
TIMELINE
Jun 13 Reserved by CNA
Jun 13 Published (CNA: VulDB)
emarket-design Customer Support Ticket System & Helpdesk — WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H N N 7.5 .0051 41.4 —
AFFECTED
Product Versions Fixed
Customer Support Ticket System & Helpdesk unspecified —
TIMELINE
May 28 Reserved by CNA
Jun 13 Published (CNA: Wordfence)
Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 9.3 .0044 36.9 —
AFFECTED
Product Versions Fixed
BUK TS-G Gas Station Automation System 2.9.1 – —
TIMELINE
Jun 13 Public exploit reference published
Jun 13 Reserved by CNA
Jun 13 Published (CNA: TuranSec)
ladela Online Scheduling and Appointment Booking System – Bookly — Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0044 36.6 —
AFFECTED
Product Versions Fixed
Online Scheduling and Appointment Booking System – Bookly unspecified —
TIMELINE
Apr 3 Reserved by CNA
Jun 13 Published (CNA: Wordfence)
Grafana Grafana Operator — Operator - Namespaced User Path Traversal
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N N N N 6.4 .0036 29.3 —
AFFECTED
Product Versions Fixed
Grafana Operator unspecified —
TIMELINE
Jun 9 Reserved by CNA
Jun 13 Published (CNA: GRAFANA)
aurelienlws LWS Optimize – All-in-One Speed Booster & Cache Tools — WS Optimize – All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File Read
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H N N 4.9 .0034 26.7 —
AFFECTED
Product Versions Fixed
LWS Optimize – All-in-One Speed Booster & Cache Tools unspecified —
TIMELINE
Jun 12 Reserved by CNA
Jun 13 Published (CNA: Wordfence)
john-dagelmore GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites — GPTranslate <= 2.31 - Unauthenticated Stored Cross-Site Scripting via REST API Translation Storage
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0032 24.4 —
AFFECTED
Product Versions Fixed
GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites unspecified —
TIMELINE
May 20 Reserved by CNA
Jun 13 Published (CNA: Wordfence)
fooplugins Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel — Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0030 22.8 —
AFFECTED
Product Versions Fixed
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel unspecified —
TIMELINE
May 20 Reserved by CNA
Jun 13 Published (CNA: Wordfence)
softaculous Page Builder: Pagelayer – Drag and Drop website builder — Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0029 21.8 —
AFFECTED
Product Versions Fixed
Page Builder: Pagelayer – Drag and Drop website builder unspecified —
TIMELINE
Feb 13 Reserved by CNA
Jun 13 Published (CNA: Wordfence)
SourceCodester CET Automated Grading System with AI Predictive Analytics index.php cross site scripting
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N P N L N 2.1 .0027 18.5 —
AFFECTED
Product Versions Fixed
CET Automated Grading System with AI Predictive Analytics 1.0 – —
TIMELINE
Jun 13 Reserved by CNA
Jun 13 Published (CNA: VulDB)
Unknown Store Locator WordPress — Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H R C L N N 3.4 .0025 16.4 —
AFFECTED
Product Versions Fixed
Store Locator WordPress unspecified —
TIMELINE
May 20 Reserved by CNA
Jun 13 Published (CNA: WPScan)
Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P L N H L L 5.6 .0024 15.9 —
AFFECTED
Product Versions Fixed
Koha unspecified —
TIMELINE
Apr 16 Reserved by CNA
Jun 13 Published (CNA: TuranSec)
softaculous Page Builder: Pagelayer – Drag and Drop website builder — Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0022 13.0 —
AFFECTED
Product Versions Fixed
Page Builder: Pagelayer – Drag and Drop website builder unspecified —
TIMELINE
Feb 26 Reserved by CNA
Jun 13 Published (CNA: Wordfence)
tigroumeow Meow Gallery — Meow Gallery <= 5.4.4 - Missing Authorization to Authenticated (Author+) Shortcode creation
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0021 12.0 —
AFFECTED
Product Versions Fixed
Meow Gallery unspecified —
TIMELINE
Jan 21 Reserved by CNA
Jun 13 Published (CNA: Wordfence)
CodeAstro Student Attendance Management System createStudents.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N H N L L L 2.0 .0021 12.1 —
AFFECTED
Product Versions Fixed
Student Attendance Management System 1.0 – —
TIMELINE
Jun 13 Reserved by CNA
Jun 13 Published (CNA: VulDB)
codesupplyco Canvas — Canvas <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Block Attribute
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0020 10.1 —
AFFECTED
Product Versions Fixed
Canvas unspecified —
TIMELINE
May 26 Reserved by CNA
Jun 13 Published (CNA: Wordfence)
Google MCP Toolbox for Databases — The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all i…
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N A H H H 9.4 .0015 5.0 —
AFFECTED
Product Versions Fixed
MCP Toolbox for Databases unspecified —
TIMELINE
Jun 8 Reserved by CNA
Jun 13 Published (CNA: Google)
Unknown Store Locator WordPress — Agile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_name
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H R U L L N 3.5 .0014 4.3 —
AFFECTED
Product Versions Fixed
Store Locator WordPress unspecified —
TIMELINE
May 20 Reserved by CNA
Jun 13 Published (CNA: WPScan)
Red Hat Red Hat Enterprise Linux 8 — Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0014 4.0 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 8 unspecified 0:2.10.9-26.el8_10
Red Hat Enterprise Linux 6 unspecified —
Red Hat Enterprise Linux 7 unspecified —
TIMELINE
Jun 12 Reserved by CNA
Jun 13 Published (CNA: redhat)
Red Hat Red Hat Enterprise Linux 8 — Abrt: unsanitized systemd journal content written to dump directory files enables content injection
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U N H N 5.5 .0013 3.1 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 8 unspecified 0:2.10.9-26.el8_10
Red Hat Enterprise Linux 6 unspecified —
Red Hat Enterprise Linux 7 unspecified —
TIMELINE
Jun 12 Reserved by CNA
Jun 13 Published (CNA: redhat)
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support — Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump directories
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0010 1.1 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 7 Extended Lifecycle Support unspecified 0:2.1.11-61.el7_9
Red Hat Enterprise Linux 8 unspecified 0:2.10.9-26.el8_10
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support unspecified 0:2.10.9-25.el8_4.1
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On unspecified 0:2.10.9-25.el8_4.1
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support unspecified 0:2.10.9-25.el8_6.1
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On unspecified 0:2.10.9-25.el8_6.1
Red Hat Enterprise Linux 8.8 Telecommunications Update Service unspecified 0:2.10.9-25.el8_8.1
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions unspecified 0:2.10.9-25.el8_8.1
Red Hat Enterprise Linux 6 unspecified —
TIMELINE
Jun 12 Reserved by CNA
Jun 13 Published (CNA: redhat)
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support — Abrt: chownproblemdir succeeds during active post-create event processing due to inadequate locking
AV AC PR UI S C I A CVSS EPSS %ile KEV
L H L N U H H H 7.0 .0009 0.6 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 7 Extended Lifecycle Support unspecified 0:2.1.11-61.el7_9
Red Hat Enterprise Linux 8 unspecified 0:2.10.9-26.el8_10
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support unspecified 0:2.10.9-25.el8_4.1
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On unspecified 0:2.10.9-25.el8_4.1
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support unspecified 0:2.10.9-25.el8_6.1
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On unspecified 0:2.10.9-25.el8_6.1
Red Hat Enterprise Linux 8.8 Telecommunications Update Service unspecified 0:2.10.9-25.el8_8.1
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions unspecified 0:2.10.9-25.el8_8.1
Red Hat Enterprise Linux 6 unspecified —
TIMELINE
Jun 12 Reserved by CNA
Jun 13 Published (CNA: redhat)
Methodology
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-13 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.